• 0 Posts
  • 14 Comments
Joined 1 year ago
cake
Cake day: July 15th, 2023

help-circle
  • If you do not trust Tailscale as a company, here is an open source re-implementation of the server called headscale. Some/all clients are open source as well. So, you can review all components yourself or pay for a professional third-party review. Otherwise, if you take a binary blob from any origin, including Tailscale, and have it run with privileges on your server, there are few limits on what this blob can do. Yes, backdoors are technically possible, but probably bad for Tailscale’s business if that ever came to light.







  • Maybe the first question is what your budget is, both regarding money and time. For example, you could buy a pre-configured NAS from Synology or QNAP, which requires less technical skills but more money, or a home-made solution reusing used components (but fresh disks for reliability). Depending on your electricity costs, you may want to choose a low-power solution or something which you power off when not used. For storage, maybe a three-disk RAID5 is a good compromise. For backups, plain S3 cloud storage encrypted via restic is a good idea.






  • Backups serve different purposes and if encryption by malware is a threat, you have to do backups differently, as opposed to, for example, hardware failure, where your NAS is a valid approach. To protect against encryption malware, you must make your backups inaccessible. One example are read-only backup media like DVD-ROMs. Another example is to make regular backups on tapes or HDDs and lock them up somewhere. You only take them out after you have wiped all computers that were affected by malware.



  • Most comments comments mention Brother, but for me, Oki is working like a charm. Using a B431dn (b/w, duplex) and a C531dn (color, duplex) with PPD files from OpenPrinting. Older models though, not sure if Oki dropped quality in favour of DRM since.

    Rules of thumb:

    1. Laser instead of ink unless you specifically know that you need/want ink.
    2. Stay away from HP, Canon, and probably Epson. HP, like IBM, has long lost its aspiration for quality.
    3. Stay away from anything that is ‘smart’ or ‘cloud’.